Security & data posture
Enterprise buyers need a clear answer to where data lives, who can see it, and how closure records stay trustworthy — even while the product is early.
Concept
Honest early-stage posture
We do not claim certifications we have not earned. This page explains how CADS handles workspace data today, what is on the roadmap, and where to read the legal detail in our Privacy policy.
Concept
What lives in CADS
CADS stores investigation and closure records for your workspace — not a copy of your entire ITSM.
- Account identifiers from your sign-in provider (for example email and name).
- Case and decision content you enter: reasoning, alternatives, evidence links, ownership, timestamps.
- Workspace closure policy (Guardrail or Enforced), closure evaluations, and soft-exception records.
- Integration metadata needed to link tickets and evaluate closure — tickets themselves stay in Jira or ServiceNow.
Pattern
Encryption
- Data in transit is protected with TLS for the web application and API.
- Data at rest is encrypted by the hosting and database platform we run on; ask us for the current region and provider details during a pilot.
- Evidence is typically linked by URL rather than duplicated as bulk file stores inside CADS.
Application
Authentication & access control
- Today: sign-in via supported identity flows (for example Google or email one-time codes) as offered in the product.
- Workspace membership and roles gate who can change policy, document exceptions, and work cases.
- SSO / SAML for enterprise IdPs is on the roadmap — available to discuss in pilot scoping rather than as a self-serve toggle today.
- RBAC continues to deepen with workspace administration; current controls focus on team membership, policy ownership, and exception authority.
Application
Audit trail & retention
- Closure evaluation, decisions, and soft exceptions form an append-oriented trail intended for managers and auditors.
- Audit-oriented export is part of the product story for regulated teams — ask during pilot for the current export shape.
- Retention follows your workspace and our Privacy policy; we do not silently rewrite history to make a closed case look cleaner after the fact.
Concept
Security questions
For questionnaires, region preferences, or SSO timing, write to hello@cadslab.com or use Get in touch from the site. We would rather answer plainly than overclaim.
Ready to apply this?
Start a decision in CADS →